Show filters
82 Total Results
Displaying 61-70 of 82
Sort by:
Attacker Value
Unknown
CVE-2020-27158
Disclosure Date: October 27, 2020 (last updated February 22, 2025)
Addressed remote code execution vulnerability in cgi_api.php that allowed escalation of privileges in Western Digital My Cloud NAS devices prior to 5.04.114.
0
Attacker Value
Unknown
CVE-2020-27160
Disclosure Date: October 27, 2020 (last updated February 22, 2025)
Addressed remote code execution vulnerability in AvailableApps.php that allowed escalation of privileges in Western Digital My Cloud NAS devices prior to 5.04.114 (issue 3 of 3).
0
Attacker Value
Unknown
CVE-2020-15816
Disclosure Date: July 17, 2020 (last updated February 21, 2025)
In Western Digital WD Discovery before 4.0.251.0, a malicious application running with standard user permissions could potentially execute code in the application's process through library injection by using DYLD environment variables.
0
Attacker Value
Unknown
CVE-2020-12427
Disclosure Date: May 13, 2020 (last updated February 21, 2025)
The Western Digital WD Discovery application before 3.8.229 for MyCloud Home on Windows and macOS is vulnerable to CSRF, with impacts such as stealing data, modifying disk contents, or exhausting disk space.
0
Attacker Value
Unknown
CVE-2020-10951
Disclosure Date: April 15, 2020 (last updated February 21, 2025)
Western Digital My Cloud Home and ibi devices before 2.2.0 allow clickjacking on sign-in pages.
0
Attacker Value
Unknown
CVE-2019-10705
Disclosure Date: March 10, 2020 (last updated February 21, 2025)
Western Digital SanDisk X600 devices in certain configurations, a vulnerability in the access control mechanism of the drive may allow data to be decrypted without knowledge of proper authentication credentials.
0
Attacker Value
Unknown
CVE-2019-11686
Disclosure Date: March 10, 2020 (last updated February 21, 2025)
Western Digital SanDisk X300, X300s, X400, and X600 devices: A vulnerability in the wear-leveling algorithm of the drive may cause cryptographically sensitive parameters (such as data encryption keys) to remain on the drive media after their intended erasure.
0
Attacker Value
Unknown
CVE-2019-10706
Disclosure Date: March 10, 2020 (last updated February 21, 2025)
Western Digital SanDisk SanDisk X300, X300s, X400, and X600 devices: The firmware update authentication method relies on a symmetric HMAC digest. The key used to validate this digest is present in a protected area of the device, and if extracted could be used to install arbitrary firmware to other devices.
0
Attacker Value
Unknown
CVE-2020-8960
Disclosure Date: February 20, 2020 (last updated February 21, 2025)
Western Digital mycloud.com before Web Version 2.2.0-134 allows XSS.
0
Attacker Value
Unknown
CVE-2020-8959
Disclosure Date: February 19, 2020 (last updated February 21, 2025)
Western Digital WesternDigitalSSDDashboardSetup.exe before 3.0.2.0 allows DLL Hijacking.
0